{"id":6040019,"date":"2015-04-21T17:56:49","date_gmt":"2015-04-21T17:56:49","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/possible-hack-alert\/"},"modified":"2016-08-24T15:01:19","modified_gmt":"2016-08-24T15:01:19","slug":"possible-hack-alert","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/possible-hack-alert\/","title":{"rendered":"Possible Hack Alert"},"content":{"rendered":"<p>I am pretty sure my website has been hacked.  Luckly I have installed a security plugin that (among other things) scans my files for any changed files.  I has located 3 files which were added at a time that I was not modifying code in my website.<\/p>\n<p>Upon investigation these file seem highly suspicious.  The code in them seems like hacker code (confusing and not normal code), and also, the files added are named extremely similar to the standard WordPress core files.<\/p>\n<p>I am looking for help form the community and also to alert the community if this is truly a hack.<\/p>\n<p>Files added that are suspicious are:<br \/>\n\/wp-logon.php<br \/>\n\/wp-radmin.php<br \/>\n\/wp-content\/plugins\/tinymce-advanced\/mce\/code\/wp-comments-blog.php<\/p>\n<p>There were added in the order listed above, seconds apart from one another.<\/p>\n<p>I am running wordpress version 4.1.1<br \/>\nI am running Elegant Themes Divi Theme version 2.2 (I will also post on the Elegant Theme support site just in case)<\/p>\n<p>Plugins running are:<br \/>\nAdmin Menu Editor &#8211; Version 1.4.3<br \/>\nAll In One WP Security &#8211; Version v3.9.0<br \/>\nCMS Tree Page View &#8211; Version 1.2.31<br \/>\nContact Form 7 &#8211; Version 4.1.1<br \/>\nCustom Facebook Feed &#8211; Version 2.3.4<br \/>\nDuplicate Post &#8211; Version 2.6<br \/>\nEnable Media Replace &#8211; Version 3.0.3<br \/>\nEnvira Gallery Lite &#8211; Version 1.2.1<br \/>\nGlobal Content Blocks &#8211; Version 2.0.1<br \/>\nGoogle Analytics by Yoast &#8211; Version 5.3.3<br \/>\nGoogle Places Reviews &#8211; Version 1.1.3<br \/>\nGoogle XML Sitemaps &#8211; Version 4.0.8<br \/>\nImsanity &#8211; Version 2.3.5<br \/>\nJetpack by WordPress.com &#8211; Version 3.4.3<br \/>\nMedia File Sizes &#8211; Version 1.8<br \/>\nTinyMCE Advanced &#8211; Version 4.1.7<br \/>\nUnder Construction &#8211; Version 1.12<br \/>\nUser Role Editor &#8211; Version 4.18.3<br \/>\nWordPress SEO &#8211; Version 2.0.1<br \/>\nWP-Optimize &#8211; Version 1.8.9.10<\/p>\n<p>Of course I have no idea what plugin might have been vulnerable, of maybe the theme??  I am a very experienced developer, but the honest truth is that I don&#8217;t even know where to begin digging through these plugins to determine the breach.  Or, maybe it was a breach through FTP or through my hosting provider (godaddy).<\/p>\n<p>For now, I have deleted the files, I desperately hope they do not return, but if the security hole is still there then they likely will.<\/p>\n<p>I will go and update wordpress, every plugin, and change FTP passwords.<\/p>\n<p>If anyone can suggest other items to look at, please let me know!!<\/p>\n","protected":false},"template":"","class_list":["post-6040019","topic","type-topic","status-closed","hentry","topic-tag-all-in-one-security"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/6040019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/6040019\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=6040019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}